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Deterministic Quantum Distribution of a d-ary key 
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We present an extension to a d-ary alphabet of a recently proposed deterministic quantum key 
distribution protocol. It relies on the use of mutually unbiased bases in prime power dimension d, 
for which we provide an explicit expression. Then, by considering a powerful individual attack, we 
show that the security of the protocol is maximal for d = 3. 
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I. INTRODUCTION 



Quantum Key Distribution (QKD)is recognized to complement the One Time Pad to a secure system for reliable 
transfer of confidential information A paradigm for QKD (not exploiting entanglement) is the pioneering BB84 
protocol Q. It allows two remote parties (Alice and Bob) to share a secret key by a unidirectional use of a quantum 
channel (supplemented by a public authenticated classical channel) . 

Protocols like BB84 have a probabilistic character, in the sense that, on each use of the quantum channel, the 
Q-f sender (Alice) is not sure that the encoded symbol will be correctly decoded by the receiver (Bob). Tipically, this 
only happens with probability 1/2. 

Recently a new generation of protocols has been introduced making the QKD process deterministic [E Q, S, @] . In 
this case Alice is sure about the fact that Bob will exactly decode the symbol she has encoded. This paradigm shift 
has been realized by a bidirectional use of the quantum channel. These new generation protocols are more versatile 
than the old generation ones and are supposed to outperform them. 
■ As much as like extensions of BB84 to larger alphabets have been developed 0,0] , there is a persistent aim to also 
extend the protocol of to larger alphabets, that is to higher dimensions. A construction has been recently devised 
for a tri-dimcnsional alphabet 

Etna 

, and then another for a continuous infinite-dimensional alphabet [111 ]. 



> 

o 

Here we present a protocol that realizes an extension of the deterministic protocol of [6[ to a d-ary alphabet. Since 
^-J. , our construction is based on Mutually Unbiased Bases (MUB) 

Hi EE EJ El, 

it holds only for prime power dimensi 



ions 



d. We will provide an explicit expression for MUB encompassing powers of both even and odd primes, by correcting 
■ the one given in HI ■ 

, We then consider a powerful individual attack on the forward and backward path of the quantum channel and we 
^ ' show that the security for d = 3, 4, 5 is higher than that at d = 2 and is maximal for d = 3. 
• i— i 

X 

II. QUDITS AND MUTUALLY UNBIASED BASES 

a ; 

Let us consider a qudit, i.e., a d-dimensional quantum system, and indicate with Hd the associated Hilbert space. 
A set of orthonormal bases in Hd is called a set of Mutually Unbiased Bases (MUB) if the absolute value of the inner 
product of any two vectors from different bases is l/Vd [l~2l . IE 14. 15|. 



It is known that in Hd, when d is prime power, there exists a maximal set of d + 1 MUB [12j, [l3j, [lj, [l5(. Here, we 
focus on this case. 

From now on we assume that d = p m , with p a prime number and m positive integer, and we denote the d+l MUB 
of Hd by |u* ), with k = 0, 1, . . . , d and t = 0, 1, . . . , d — 1 labelling the basis and the vector in it respectively. 
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Thus, for every k,k' = 0,1, ... ,d and every t, t' = 0, 1, . . . , d — 1, the following equality holds: 



(vt\v$) \ =^(l-Sk,k') + S t ,t'Sk,k', 



1 



(1) 



where 5 stands for the Kronecker delta. 

We deal with the Galois field G = ¥(p m ) of d elements. We denote by © and © respectively the addition and 
the multiplication in the field G (by © and the subtraction and the division in G). Usually, an clement of G is 
represented by a m-tuple (go,gi, ■ ■ ■ ,g m -\) of integers modulo p. According to this representation, © corresponds to 
the componentwise addition modulo p. 

Following 10|, we identify G with {0, 1, . . . , d — 1}, paying attention to distinguish the operations in the field from 
the usual ones. Namely, we identify (go,gi, ■ ■ ■ ,9m-i) with the integer g = X)T=o 9nP n - This allows us to consider 
the vector label t in \ vt) as an element of G. 



Let us denote the p-th root of unity by 



J2tt/p 



(2) 



It is proved in [3| that 



u j ■ J = uj m with j, I £ G 



(3) 



and 



d-l 

E< 

j=0 



dSi.o with I G G. 



(4) 



We choose {|i^)}t = o d-i as the computational basis and use the explicit formula given in 16| to express the 

vectors of any other basis in the following compact way: 



d-l 



—y 



e«0t/ w (fe-l)05f05f^|„O 



(5) 



q=0 



where k = l,...,d and t = 0, 1, . . . , d— 1. In particular for k = 1: 

d-l 



k 1 ) 



Vd 



LO e " Qt \vl) 



(G) 



q=0 



As it is pointed out in [16( , for p odd the square root coincides with the division of the exponent by 2 in G and it 
is uniquely determined. On the contrary, for p = 2 it is necessary to unambiguosly determine the square root's sign. 
This is given by (see Appendix) 



O-i)0<?0<?^ 



m — 1 

IT 

n=0 



(j-l)02' l 02" ,(j-l)02"0( q mod 2") 



(7) 



With this in mind, the expression ([5]) satisfies the condition ((T|) of MUB, for d any prime power, both even and odd 
(see Appendix for the proof). Notice that this does not happen in [l6| in the even case. Hence, in the following we 
will make use of ([5]) without distinguishing the two cases. 



III. THE PROTOCOL 

Moving from the protocol of we consider Bob sending to Alice a qudit state randomly chosen from the set 
{\ v t)}t=o 'd-i °f MUB. Then, whatever is the state, Alice has to encode a symbol belonging to a d-ary alphabet 
A = {0, . . . , d — 1} in such a way that Bob will be able to unambiguously decode it (deterministic character of 
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the protocol). The alphabet A can be identified with the Galois field G. Moreover, let us consider the unitary 
transformations V a for a £ A, defined by 

v o o l«?>=" t0a k°>> (8) 

which can be regarded as the generalized Pauli Z operators. 

Then, Alice encoding operation will be the shift operation realized by the operator Vq with a £ A on all the MUB 
but the computational one, that is for k > 0: 

VB>*> = ±^^^\^-^^v° q ) = |«* eo ). (9) 

q—0 

In such a case, Bob receiving back the state |v*Q a ) can unambiguously determine a by means of a projective 
measurement onto the fc-th basis. In fact, he will get the value 

b = tQa (10) 

from which, knowing t, he can extract a. 
Then, the protocol runs as follows: 

1. Bob randomly prepares one of the d 2 qudit states with k = 1, . . . , d and t = 0, . . . , d — 1, and sends it to 
Alice. 

2. Alice, upon receiving the qudit state has two options. 

a) With probability c ^ 0, she performs a measurement by projecting over a randomly chosen basis among 
the d bases with k = 1, . . . , d (Control Mode). She then sends back to Bob the resulting state. 

b) With probability 1 — c, she encodes a symbol a € A by applying the unitary operator V a (Message Mode). 
She then sends back to Bob the resulting state. 

3. Bob, upon receiving back the qudit state, performs a measurement by projecting over the basis to which the 
qudit state initially belonged. 

4. At the end of the transmission, Alice publicly declares on which runs she performed the control mode and on 
which others the message mode. In the first case, Alice announces the bases over which she measured. Then, by 
public discussion, a comparison of Alice's and Bob's measurements results is performed over coincident bases. 
In the ideal case (noiseless channels and no eavesdropping) their results must coincide. 

In the message mode runs, Bob gets the encoded symbol a as discussed above. 

Notice at the above point 2. the deterministic character of the protocol given by the possibility for Alice, besides to 
decide when to encode, to determine the message (key) sequence, since she knows that Bob will unambigously decode 
each character of the message (key) . 

IV. SECURITY OF THE PROTOCOL 

Among individual attacks the most elementary one is the Intercept- Resend. Suppose Eve, to learn Alice's operation, 
performs projective measurements on both paths of the traveling qudit, randomly choosing the measuring basis. She 
will steal the whole information for each message mode run, indipedently from the chosen basis. However, in each 
control mode run with coincident bases for Alice and Bob, she can guess the correct basis with probability 1/d, and in 
this case she is not detected at all. If otherwise Eve chooses the wrong basis, she still has a probability 1/d to evade 
detection on the forward path and probability 1/d on the backward path, leading to an overall probability 1/d 2 to 
remain undetected. This means that the double test of Alice and Bob reveals Eve with probability (d 2 — l)(d— l)/d 4 , 
including the cases of non-coincident bases. 
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We are going to prove the security of the protocol against a more powerful individual attack. Quite generally, in 
individual attacks Eve lets the carrier of information interact with an ancilla system she has prepared and then try 
to gain information by measuring the ancilla. In this protocol she has to do that two times, in the forward path (to 
gain information about the state Bob sends to Alice) and in the backward path (to gain information about the state 
Alice sends back to Bob, hence about Alice's transformation). Moreover, by using the same ancilla in the forward 
and backward path, Eve could benefit from quantum interference effects (see Fig. [I]). 

In particular, we consider the unitary transformation describing the attack as controlled shifts {V^jzgA, where the 
controller is the traveling qudit, while the target is in the Eve's hands. That is, C{Vq}i^a '■ T~(-d <8> T~td — * "Hd <£> "Hd 
defined as follows: 

K)K) civ " }leA : Kwt^K) = lOkW- (ii) 

We remark that, in this definition, the controller as well as the target states are considered in the dual basis for the 
sake of simplicity. Other choices (except the computational basis) will give the same final results. 
Then, we consider Eve intervening in the forward path with (CjVglig^) -1 , defined by 

K)K) (^i^ 1 \vi)v ^\vi) = KK e(etl) ) = K)K mi ), (12) 

and with C{Vq}i^a in the backward path. 



B \v k t) 

£ K'o) 



B a - 



B 




FIG. 1: The scheme summarizing our protocol. Labels B and £ stand for Bob's and Eve's qudit systems respectively. Label A 
denotes Alice's operation on Bob's qudit. (C{Vq }; 6 a) _1 and C{Vo}ieA represent the eavesdropping operations on the forward 
and backward path respectively. 



A. Message Mode 

Now, let us analyze in detail the transformations of the quantum states on an entire message mode run. 
Attack on the forward path. 

The initial Bob state is one of the d 2 states \vf), with k = 1, . . . , d and t = 0, .. . , d— 1. Then, Eve initially prepares 
the ancilla state |uq)£ in the dual basis and performs the controlled operation. Hence, we get 

\v k t )s\vl) £ ( c{v °' }i6 < Y^{vl\v k t )\vl) B \vl) £ = Y,{vl\v k t )\vi) B \vl) £ . (13) 
/i=o h=a 
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Encoding. 

The Bob's qudit state undergoes the shift Vq with a e A, then from (fT3|) we get 



d-1 



h=0 



Y,( v >t)\vlea)B\vl) £ . (14) 

Attack on the backward path. 



The state p^|) undergoes a C^V^}/^ operation, hence we have 

, d-1 d-1 

C{VoheA , Y,( v >t)\vlea)B\v 1 he{hea) ) £ = Y,( v i\ v t)\v 1 hea )B\v 1 a ) £ = \v k tea )e\v\) £ . (15) 

h=0 h=0 

Then, Eve measures her ancilla system by projecting in the dual basis, according to the chosen initial ancilla state. 

We notice that the controlled operations performed by Eve, as well as her final measurement, left unchanged Bob's 
qudit state. Hence, Bob's measurement by projection in the fe-th basis to which the initial state belonged, always 
allows him to obtain the symbol a Alice has encoded [see (|10j)]. 

On the other hand, Eve gets with probability 1 as the result of her measurement. Therefore, she is able to 
exactly determine the encoded symbol a as well and she steals the whole information, quantified in bits, 

Is = log 2 d (16) 

on each message mode run. 

B. Control Mode 

We would like to evaluate the probability Pg Alice and Bob have to reveal Eve on each control mode run. Alice 
and Bob only compare the results of their measurements when, by public discussion, they agree on the used basis. 

Let us focus on the case Alice and Bob use the same basis k, keeping in mind that it happens with probability 1/d. 
The situation is different for k = 1 and k ^ 1, due to the Eve's choice of using the dual basis for her ancilla. 

1) For k = 1, on the forward path we have 

I 1 \ i 1 \ (C{V }(<=a) 1 I i \ I i \ 

\vt)B\vo)e ► \vt)B\v t ) £ . (17) 

Alice, measuring in the dual basis, gets t with probability 1 and projects into On the backward path we 

have 

\v}) B \v})e C{V ^ A , \v]) B \vl et )s = \vl) B \vl) s . (18) 

Bob, in turn, by measuring in the dual basis gets t with probability 1. Thus, Alice and Bob have perfect 
correlation and P £ = 0. 

2) For k = 2, . . . , d, we get on the forward path 

d-1 l _j d-1 

\v k t ) B \vl)s - E^h'K^K^ ( c{v °>' eA) , 5>/il«?M>Bl«i>*- (19) 



h=0 h=0 



By expressing the vectors of the dual basis in terms of the basis k used by Bob, we rewrite the right hand side 
of (US) as 



d-1 



£<^k fe )£K>fc>k fe > B K> £ . (20) 



h=0 s=0 
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At this point Alice measures in the basis k. The result of her measurement is to project into \v^,}, whatever 
t' € A is, with probability 

d-1 d-1 d-1 1 1 

£ \(vl\v*)(v*\vl)\ 2 = J2 \(vl\v?)\ 2 \(4K)\ 2 = J2^p = d (21) 

h=0 h=0 h=0 

according to definition of MUB. 

Among the d possibilities we distinguish two cases. 

a) t' = t, occurring with probability 1/d, for which the resulting state from (f2TJ|) is 

d-i 1 d-1 

VdY / (vl\vh(vhvl)\v^ S \vl) £ = y =Y,\ v t)B\v 1 h ) £ - (22) 
h=0 vd h=Q 

We have now to apply the C{Vq }i£A operation of the backward path. Thus, ([2^]) transforms as follows 

d-1 d-1 d-1 

h—0 h'—O h—Q 



h'=0 h=0 * r=0 



h,'=0 

where r = hQ h'. 

It results that Eve's attack does not alter the eigenvector |i>*)b. Hence, Bob upon his measurement will 
get t with probability 1. Then, neither Alice nor Bob outwit Eve's attacks. 

b) t' 7^ t, occurring with probability (d— l)/d, for which Alice, getting a state different from the one initially 
sent by Bob, outwits Eve in the forward path. Hence, in this case, we do not need to explicitly evaluate 
the state change in the backward path. 

In summary, from the analyzed cases, we have: 

• 1/d the probability with which Bob and Alice measure in the same basis k; 

• (d — l)/d the probability of Bob choosing the initial state \Vf) from any basis but the dual one, that is k ^ 1; 

• (d — l)/d the probability that the state sent by Bob gives a measurement result \v^,) with t' ^ t to Alice. 
We then conclude that the probability for Alice and Bob to outwit Eve on each control mode run is 

In Fig. [2] we show the behavior of P$ versus the order d of the alphabet. Interestingly enough, the values of Pg at 
d = 3,4, 5 are higher than that at d = 2. In particular, Pg has a maximum at d = 3 showing that this dimension 
represents the optimal compromise between two different trends. On the one hand, the probability (d — 1) /d 2 of 
revealing Eve in each successful control mode run (that is when the bases of Alice and Bob coincide) increases towards 
1 when increasing the dimension d. On the other hand, the efficiency of the whole control process decreases according 
to the probability 1/d for each control mode run to succeed. 
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FIG. 2: The probability Ps versus the dimension d (bars correspond to prime power numbers). 



CONCLUDING REMARKS 



We have proposed a deterministic cryptographic protocol working with a d-ary alphabet and exploiting a bidirec- 
tional quantum channel. When considering an attack performed by means of controlled operations on both directions 
of the quantum channel, we have found that Eve can steal the total amount of information Ig (see (|16|1). while the 
probability Pg to outwit her presents a maximum for d = 3 (see (|25jl). 

Contrarily to probabilistic protocols, the deterministic nature of this protocol also allows the realization of Quantum 
Direct Communication (QDC) between legitimate users In this case Alice and Bob (after authentication) 

can communicate directly the meaningful message without encryption. However, for this kind of communication only 
an asymptotic security can be proven. In fact, if we assume that Eve wants to perform her attack on each message 
mode run, without having been detected in the previous control mode runs, then the probability is given by following 
geometric series: 



(1 - c) + c(l - P £ )(l - c) + c 2 (l - Pg) 2 (l - c) + . . . = 



1 -c 



l-c(l-Pe) 



(26) 



Thus, being Ig the quantity of information that Eve eavesdrops in a single attack, the probability that she success- 
fully eavesdrops an amount of information / is 



1 - c 



I/Is 



1 - c(l - P £ ) 



(27) 



with Ig and Pg given in (fro)) and (|2"5|) respectively. 

We observe that such a probability exponentially decreases towards as a function of / for each given dimension 
d. So, (|2T|) expresses the asymptotic security of the direct communication use of the protocol. 

However, in this case the probability for Alice and Bob to detect Eve before she can eavesdrop a fixed amount of 
information, that is the complement of probability in (|27p . is maximal for d = 2. 

It is interesting to notice that the optimal dimension depends on the specific task of the protocol (QKD or QDC). 
Therefore, we believe that this work might open up new horizons for deterministic cryptographic protocols involving 
finite dimensional systems. 
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APPENDIX A 



By referring to 16(, let us denote by Vf the operators given by the composition of the shifts in the computational 

d-l 

V? =V$-V? = Y," m)0j \t ®l)(t\. (Al) 



and the dual basis, that is 

d-l 



This set of operators coincides with the Generalized Pauli Group (see 14|). The V^'s are d 2 unitary transformations 
which satify the following composition law 

V j. V f =w (iOJ') V M\ ( A2) 

and, up to phases, they form d + 1 commuting subgroups of d elements that have only the identity in common. The 
fc-th subgroup, with k = 0, . . . , d, admits {\v^ )}t=o,...,d-i as diagonalizing basis. Its elements are denoted by Uj e with 
I = 0, . . . , d — 1, and they are required to satisfy: 

Cjffii' = ^ ■ , (A3) 

d-l 

t=o 

Uj" = V"/ fc " 1)0Z up to a phase which is 1 for I = 0. (A5) 

It is important to point out that (|A2j) . (|A3j) . (|A4|) and (|A5|) must be guaranteed at the same time. In [l^ . the 
following relation is obtained from them: 

Uf = ( w e(fc-i)0i0i^ v, (fc - 1)0 ' (A6) 

In the odd prime power case such expression is completely determined and the phase is a p-th root of unity. In fact 
the square root can be interpreted as the division of the exponent by 2 in the Galois field G. 

This is no longer true in the even prime power case. In this case the phase is not a 2-nd root of unity but a 4-th 
root of unity, that is it can also assume the values ±i, other than ±1. Moreover, the sign of it is still undetermined. 
The determination of such sign provided in [l6| is uncorrect. 



Below we correctly develop the last step of (32) in 16( getting the right sign, and consequently the square root's 
sign in ([5]), as indicated in (J7J). 

First of all, we observe that for p = 2 we have u> = — 1. 

In 16| it has been implicitly chosen the determination of the square root of Ci/ fc-1 ) 02 02 as to be ^(k- 1 )© 2 © 2 . 



Then, we have: 

m — 1 m— 1 



m— 1 1 



71=0 



m— 1 



n=0 




J] z^-D 02 " 02 " J] y^- 1 ' 02 . (A7) 
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Let no, ni, ■■ -nh be the indices rij such that l nj = 1. By taking into account (|A2[) . the second product can be 
rewritten as follows. 

m— 1 /i 

[i (^„ fc - i)02 ")=n^ _i)02 " j 

n=0 j=0 



JJ w (fc-l)O(2"0©2"ie...ffi2"J-i)O2"J y(fc-l)0(2"°0...©2"fc) 



(2"0©...©2"J>) 



J~J w (fe-l)O2"J0(i mod 2"j) | y(k- 
m — 1 

(fc-l)02"0(i mod 2") | Tr(fe-l)0j 



■Q w (H)02"0(Imod2") y(k-l)Ql_ 



n=0 



Then, we have: 



m — 1 



Ul = \ TT j(fc-l)02"O2" w (fe-l)O2"0(i mod 2") ^(fc-l)OZ_ 
\ n=0 / 

This gives the correct determination of square root's sign in the phase as in ([7]), which can be rewritten as 

Tn—t m— 1 

J~J j(fc-l)02"02" w (fc-l)02"0(i mod 2") _ TT ^ _ J^Z^o l " l h (fe-l)O2"02 h ^„ (fc- 1)02" 02" _ (A10) 
n=0 n=0 

Now, by referring to j3]), we remark that an analogous property does not hold for powers of i with exponents in G. 
The reader can easily check that 

i j ■ i l = = (-iy° l °i j ® 1 . (All) 

From (|A11|1 it follows that 

( w (*-i)0'0i)i/3( £i; (*'-i)0«0i)i/a = 0(fc ) fc' > /)( w ((fc-i)ffi(*'-i))0'0i)i ) (A12) 

where we have defined 

<Kk,k',i) = (-i)i:r,ro 1 ^((fc-i)o2"02")((fe'-i)02"02")^ (A13) 

In fact, by using (|A10|) and (|A11|) . 

( w (fc-i)0'0')l( w (fe'-i)0'0^| 

m — 1 

= n(-D 



m— 1 

_ Eftio ir 1 ih(fc-l)02"02 h ji„(fc-l)02"©2" 

71 — , , . , 

_i\E;= W*(fc -l)O2"02 h ■i„(fc'-l)02 n ©2 n 



m— 1 

)T,hZo Wh((fc-l)0(fc'-l))02"02 h 



n— 

x (•_ 1 -)(i„(fc-l)02"O2")(i„(fc'-l)02"02") ji„((fc-l)0(fe'-l))02"©2" 

4>{k, k\ I) (w^- 1 )®^'- 1 )) ' ')*. (A14) 
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In particular, by assuming k' = k in (|A12[) . we get the conjugate of (oj < - k as 

0(fc,fc, g )(w (fc - 1)0 « «)i (A15) 

Consequently, the correct expression for the inner products (v k \v k ) with k, k' > 1 is the following (which does not 
coincide with (28) in 0): 



9=0 



d-l 

= - J2 Hk, k', q) 4>(k\ k', q) ^QC©*')^"^ 1 ) ^'- 1 )) ^)^. (A16) 
%=0 

In order to prove the MUB condition, we state the following elementary properties of the function <f>: 

(j)(k, k',0) = l (A17) 

ct>(k',k,q) = <t>(k,k',q) (A18) 

cf>(k, k', q) <j>(k, k', q') = <t>(k, k', q q') (A19) 

(j)(k,k,q)=OJ ( - k -V Q ' 10q (A20) 

The first and the second one come from the very definition of (j>, the third one comes from the fact that q n +q' n mod 2 = 
(<? © q')n and the fourth one from (|A12[) for k' = k. 
We also need to verify that the following equality, corresponding to (37) in [16j . 

( w (fc-l)©g©9)5( a; (fc-l)©9'09')ll = w (fc-i)0909'( w (fc-i)0(9ffig')©(«®9'))5 (A21) 

holds with the correct determination of square root's sign given by (|A10[) (this does not happen with wrong determi- 
nation of the sign given in (l^|). 

Let us consider the left hand side. It turns out to be 

771—1 

= (_ 1 )Eh;oN n ?h(fc-l)02"02^_ 1 ^^Z o 1 g; g ^(fc-l)02"02 h i g„(fc-l)02"O2" i g;(fc-l)02"02" 

n=0 
m— 1 

= TJ (_l)Eh; o 1 (9"9h+9; i <Zh)(fc-l)02™O2'^_ 1 ^„g;(fc-l)02™O2"j( g e g ')„(fc-l)O2"02™ 
n=0 



(_1)(E™=0 1 9«9; i ( fe - 1 )©2"O2") + (^™- 1 ^^-Ug„9h+9;^)(fe-l)O2"02 h ) 

m— 1 

J" Wfc-1)02"02"_ ( A22 ) 



m— 1 

X 

n=0 



For the right hand side, we have: 

w (fe-i)0g0g' ( w (fc-i)0(<?©<?')0(<?©<?')-)5 

= (-WMaErJo 1 9«2")0(Er=o 1 <4 2 ") 

m— 1 

IK- 1 ) 



m— 1 



n=0 



(_i)(2:;r 1 Er^o 1 ^(fc-i)© 2 "© 2 ^^^ 1 £^9©?% (?©<?' wfc-i)© 2 "© 2h ) 

m— 1 

-Q i (ge«')n(*-i)0a»0a» i (A23 ) 



m— 1 

X 

71 = 
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At this point, (|A21[) derives from the following sequence of equalities mod 2: 

/m— lm- 1 \ /m—ln—X 



E Y.1nq' h 2 n G2 h \ + E('?®9')n(g©9')/ l 2"0 2M 

/ m — 1 m — 1 \ /m-ln-1 \ 

= EE 9n^2' 1 2' 1 + e Ete« + + ^)2" © 2,1 



^n=0 /i=0 / \n=0 h=0 

( ni—1 \ / m— 1 n— 1 



E 3«<£2 n 2" + E E(«n«fc + 9^)2" 2 A . (A24) 



\n=0 / \n=0 h=0 / 

Finally, we can prove the MUB condition for even prime power. 

From (|A16j) . by using in the order (|A18|) . (|A19j) . (|A21|) and (|A20j) . and then relabelling the sum indices, we have 

d-1 

= j2 E <f>(k,k',<l) <(>(*', k , ,q)<f>(k,k',q')<f>(k,k,q') 

q,q'=0 

x w 90(t®*') w '?'O(t©*')( tJ ((fc-l)©(fc'-l))O9O9)|( CJ ((fc-l)®(fe'-l))0</'09')5 

= E <t>(k,k',q®q')<t>(k,k,q®q')<f>{k,k,q)<f>(k',k',q) 

q,q'=0 

x w (3©g')0(*©*') a; ((fe-i)ffi(fc'-i))0g0?V a; ((fe-i)e(fc'-i))0(9ffi9')0(gffi?')'j3 



1 d-l 

- e ^,fc',M0(fc^»^ (fc " 1)090 ^ (fe '" 1)0909 



g,/i=0 

x w 'i0(t©t') w (('=-l)©(fc'-l))O9O(9©'»)( w ((fe-l)®(fc'-l))O^0'i)5 



Now, by collecting the terms without q and then using (f5|), the previous expression can be rewritten as 

d-l d-l 

d 2 



i E ^ fc > fc '' ^ fc ' ^ ^ 0(t0t,) ( W (( fc - 1 )®( fc '- 1 )) Q " Q ' l )5 £ w ((fc-l)ffl(fc'-l))090fc 



h=0 q=0 



- e ^(fc, h) m k, h) u h ®^ ( W (( fc - i )®( fc '- i ))® h ® A )i5 ((fe _ 1)e(fc ,_ 1))0feiO . 



/i=0 



At this point we can conclude as follows, by separating the cases k ^ kl and k = k' and then using (|A17|l . (|AL9[) and 
©• 

1 1 d-i 

-7(1 - SwMk, k', 0) 4>(k, k, 0) + -4, fc ' E <^ fc ' fc < ft ) fc ' fc ) w,lG(tffit } 



h=0 



J(l-*k,*O + 3*M'X> h0(t ® t ' ) = ^(i-^.fcO + ^fe'V- (A25) 



d v ■ ' d ' ^ d 

h=0 

This gives ([1]), q.e.d. 
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